To connect a Google Workspace inbox to Smartlead, start in Smartlead's Email Accounts area, choose its managed infrastructure and Google OAuth, approve the displayed OAuth client ID in Google Admin if your organization requires it, then authorize the same mailbox in Google's consent window. You do not need to create a Google Cloud project for this managed path. The Workspace administrator should review the access scope and choose which organizational unit can use the app before approving it. Smartlead's current OAuth guide documents the path; Google's app-access guide explains the administrator's controls.
This guide was checked against those public instructions on October 1, 2026. It describes a documented setup, not a connection we made to a live Workspace. Smartlead's interface uses both “Smartlead Infrastructure” and “Shared Infrastructure” in different parts of its own guide; choose its managed OAuth route, not the separate private OAuth project flow.
Before you begin
| You need | Why it matters |
|---|---|
| A real Google Workspace user mailbox that can sign in | OAuth consent must be completed by the account you intend to connect. An alias alone is not a separate Google sign-in. |
| Access to Smartlead's Email Accounts area | The connection begins there; connecting a mailbox does not itself assign it to a campaign. |
| A Workspace administrator who can manage third-party app access | Restricted organizations may block consent until the Smartlead OAuth client is configured in Admin. Google says this requires the relevant security-settings privilege. |
| Browser pop-ups allowed for Smartlead | The Google account selector and consent screen open in a pop-up, according to Smartlead. |
| A decision about organizational scope | Google lets an administrator apply app access to the whole organization or selected organizational units. |
Do not ask a teammate to paste a mailbox password, OAuth token, or Google admin credential into Smartlead support chat or a shared setup sheet. The relevant item for the admin workflow is the OAuth client ID shown in Smartlead. An administrator can compare the app identity and requested Google scopes in the Admin console before allowing access. Google's Trusted setting can grant an app access to all Google services, including restricted services, so the approval is a real security decision rather than a harmless checkbox. Google documents Trusted, Limited and Specific Google data access; Smartlead's walkthrough specifically instructs admins to select Trusted. If your policy requires a narrower grant, have your Workspace admin assess whether Smartlead's requested scopes work with Google's specific-data option instead of assuming they do.
Step 1: Get the client ID from Smartlead
- Sign in to Smartlead and open Email Accounts.
- Select Connect Mailbox or Add Account. Smartlead's one-click OAuth instructions show Smartlead Infrastructure as the managed option and Private Infrastructure as the path for your own OAuth credentials.
- Choose Smartlead Infrastructure → Google OAuth. Smartlead displays its Google OAuth client ID in a pop-up. Copy the ID for your Workspace administrator. Do not copy an ID from a screenshot or another organization's instructions; use the value displayed in your account.
The private route is a different implementation. Smartlead's private Email Network guide requires a Google Cloud OAuth app and advises coordinating with its customer-success team. Use it only when your organization deliberately needs to own the OAuth app and has checked the plan and setup requirements. It is not a fix for a managed-app consent prompt you have not yet investigated.
Step 2: Approve the app in Google Admin, if required
This is an administrator action. In the Google Admin console, go to Security → Access and data control → API controls → Manage App Access → Configure new app. Search by the Smartlead client ID you just copied. Open the matching app, select the organization or the specific organizational units that should be allowed to connect, choose the access setting your policy permits, review the configuration, and finish. Smartlead's documented sequence chooses Trusted; Google describes the reach of that setting in its app-access documentation.
Smartlead says its approval may take up to ten minutes to propagate. Google also notes that some app-access changes may take longer. If your organization already configured this exact client ID for the intended users, the admin need not create a duplicate entry; verify its access state and scope instead.
Why use the client ID rather than only the name? Names can be similar. The ID is what ties the Google Admin entry to the OAuth client Smartlead presents. This is especially useful when several vendors, apps or organizational units are involved. Google's Admin page lets the administrator inspect the app's OAuth client ID and requested scopes.
Step 3: Complete consent as the sending mailbox
Return to Smartlead → Email Accounts, select the managed Google path, and choose Connect Account. Allow pop-ups for the Smartlead site if the Google window does not appear. Select the intended Workspace mailbox in Google's account chooser, read the requested permissions and choose Allow only if they match your organization's approved use. Smartlead lists Gmail access, sending and profile permissions in its guide. After Google redirects back, the mailbox should appear in Smartlead as Connected or Active.
Check the exact address and status in Email Accounts. Then check who owns the account and which campaign or client should use it. A connected mailbox is merely available in Smartlead; it is not proof that the sender identity, campaign assignment, DNS authentication, reply handling or sending policy is ready. Smartlead's new campaign setup guide separately describes assigning active email accounts and checking campaign controls. If you are evaluating the platform before connecting multiple inboxes, our Smartlead review covers the broader product; this article addresses the Workspace authorization problem.
Troubleshooting by symptom
| Symptom | What to check next |
|---|---|
| “This app is blocked” | Check the client ID and organizational unit in Manage App Access. Smartlead says the message is expected when a restricted Workspace has not yet approved its app. After the admin change, wait for propagation and retry consent. |
| No Google consent window | Permit pop-ups for Smartlead and start Connect Account again. This is a browser-window issue before OAuth consent. |
| Wrong Google account appears | Use Google's account chooser to select the mailbox that will actually send. Verify the address back in Smartlead before adding it to any campaign. |
| Admin cannot find the app or approve it | Confirm the copied client ID is from the active Smartlead flow, and that the admin has the Google security-settings privilege. Escalate to your Workspace admin rather than sharing admin credentials. |
| Approved but still blocked | Confirm the approval applies to that user's organizational unit and the requested scopes; allow time for propagation. If it persists, follow Smartlead's advice to contact support with a screenshot that excludes secrets. |
| Connected but not usable in a campaign | Check mailbox status and campaign assignment separately. Smartlead's campaign guide says only eligible active accounts are used for sending. Do not treat OAuth connection as a deliverability test. |
Avoid changing unrelated Google security controls to make one integration pass. Google allows an administrator to inspect app access and requested scopes, so diagnose the specific client, user and policy first. Google's admin reference and Smartlead's OAuth guide are the current sources if the interface labels change.
Decide whether this path fits
Choose managed OAuth when the administrator is comfortable approving Smartlead's Google app and wants the documented connection with no customer-owned Cloud project. Choose private Email Network OAuth only if ownership of the OAuth client is an explicit requirement and your plan and team can maintain it. Use a different sending platform if your organization cannot authorize the required Google access. Our Instantly versus Smartlead comparison is useful for that wider platform choice.
Disclosure: OutboundXYZ has a Smartlead affiliate relationship. That relationship does not change the Google permissions or turn this documentation-based guide into hands-on verification. Confirm your organization's security and sending policies before granting access.


